Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New ClickFix Attack leverages Windows Terminal for Payload Execution

Recent findings indicate a new series of ClickFix attacks leveraging Windows Terminal for direct payload execution on target systems. This method enhances the plausibility and eludes detection by avoiding the conventional Windows Run dialog.

Recent findings indicate a new series of ClickFix attacks leveraging Windows Terminal for direct payload execution on target systems. This method enhances the plausibility and eludes detection by avoiding the conventional Windows Run dialog.

The recent attack campaign encourages users to access a privileged command environment, diverging from previous methodologies. Initially identified in early 2024, ClickFix exploited fake browser errors to execute harmful commands. The prevalence of this attack method has surged by 517% in 2025, ranking it as a significant global threat vector.

Attackers employ tactics such as fake CAPTCHA pages and urgent alerts to prompt user response. A campaign identified in February 2026 specifically targets Windows Terminal, bypassing security measures meant to detect Run dialog misuse.

The campaign instructs users to use the Windows + X shortcut followed by "I" to open Windows Terminal, avoiding traditional security flags. This method places users into a command-line environment that mimics legitimate IT operations.

Microsoft's 2025 Digital Defense Report highlights ClickFix as a leading initial access method, surpassing phishing, with a 47% share of tracked attacks. The campaign's payload, Lumma Stealer, is designed to harvest credentials and sensitive browser data.

Recent findings indicate a new series of ClickFix attacks leveraging Windows Terminal for direct payload execution on target systems.
Brooke Sanders · Thehackingpost

The attack begins when a victim accesses a compromised site, where hidden scripts copy a PowerShell command to the clipboard. Users are then prompted by a deceptive CAPTCHA to paste this command into Windows Terminal.

This initiates a PowerShell process that downloads additional malicious components, including a renamed executable and a ZIP archive, which execute without user awareness. The malware establishes persistence via a scheduled task, embedding itself into browser processes to extract credentials.

Detection is complicated by the trusted status of Windows Terminal components, making it challenging for security tools to identify malicious activity.

Advertisement

Organizations should enforce policies preventing command pasting from web prompts and restrict Windows Terminal and PowerShell access to administrative accounts. Regular inspections of registry keys and scheduled tasks are recommended.

Endpoint detection tools should monitor PowerShell activities initiated by Windows Terminal, and antimalware definitions should be updated consistently across all systems.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories